{"id":4390,"date":"2024-07-10T00:00:00","date_gmt":"2024-07-10T05:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/houthi-aligned-apt-targets-middle-east-militaries-spyware"},"modified":"2024-07-10T00:00:00","modified_gmt":"2024-07-10T05:00:00","slug":"houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/10\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware\/","title":{"rendered":"Houthi-Aligned APT Targets Mideast Militaries With &#8216;GuardZoo&#8217; Spyware"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte9c0dfc2c3cac8a1\/668da36e874ac79913c4296d\/camel-Cucu_Rosa-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A threat actor which may be aligned with Houthi rebels in Yemen has been spying on military targets throughout the Middle East for half a decade now.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Their weapon of war: a custom Android surveillanceware called &#8220;GuardZoo.&#8221; GuardZoo seems to have been used to steal potentially valuable intelligence relating to the actor&#8217;s military enemies, including official documents, photos, and data relating to troop locations and movements.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The GuardZoo Campaign\">The GuardZoo Campaign<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">GuardZoo attacks begin with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/whatsapp-mobile-phishing-s-newest-attack-target\" rel=\"noopener\">malicious links distributed on WhatsApp<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and WhatsApp Business.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The links lead to fake apps hosted outside of the Google Play store. Some pertain to generic themes \u2014 like &#8220;The Holy Quran,&#8221; and &#8220;Locate Your Phone&#8221; \u2014 but most are military-oriented \u2014 &#8220;Art of War,&#8221; &#8220;Constitution of the Armed Forces,&#8221; and those relating to specific organizations like the Yemen Armed Forces, and the Saudi Armed Forces&#8217; Command and Staff College.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These various apps all deliver the GuardZoo malware.<\/span><\/p>\n<div readability=\"7\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware.png\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware.png?w=640&#038;ssl=1\" loading=\"lazy\" alt title><\/p>\n<p class=\"ContentImage-Link\">GuardZoo&#8217;s fake apps; Source: Lookout<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">GuardZoo is essentially the leaked &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/github.com\/nyx0\/Dendroid\" rel=\"noopener\">Dendroid RAT<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; with some of the fat removed, and retrofitted with dozens of commands fitting its proprietor&#8217;s spying needs. That may partly explain why the campaign, which dates back to October 2019, is only now coming to light. &#8220;If somebody uses the same tooling as as many other actors, then they can fly [under the radar] simply because they don&#8217;t stick out,&#8221; explains Christoph Hebeisen, Lookout director of security intelligence research.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Upon infection, GuardZoo&#8217;s first actions always involve disabling local logging, and exfiltrating all the victim&#8217;s files in the past seven years that match KMZ, WPT (waypoint), RTE (route), and TRK (track) file extensions. Notably, these extensions all relate to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/iot\/unpatched-gps-tracker-security-bugs-disruption\" rel=\"noopener\">GPS and mapping apps<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The malware can also facilitate the download of further malware, read information about the victim&#8217;s machine \u2014 like its model, cell service provider, and connection speed \u2014 and more.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Middle East Military Targets\">Middle East Military Targets<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To Hebeisen, &#8220;One thing that strongly indicates to us that it&#8217;s military targeting [is] the hardcoded file extensions that are very mapping-related. That targeting, to me, indicates \u2014 given that they are involved in a military conflict \u2014 that they are likely looking for tactical information from the enemy.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The majority of the 450 affected IP addresses observed by Lookout were concentrated in Yemen, though they spanned Saudi Arabia, Egypt, the United Arab Emirates, Turkey, Qatar, and Oman as well.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Houthi connection, specifically, is strengthened by the location of the malware&#8217;s command-and-control (C2) server. &#8220;It uses dynamic IP addresses, but with a telco provider that operates in a Houthi-controlled area. It&#8217;s a physical server \u2014 we got the serial number, and could actually trace it \u2014 and you likely wouldn&#8217;t want to place a physical server in enemy territory,&#8221; Hebeisen reasons.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Relative to the significance of its targets, actually defending against this campaign is quite simple. In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.lookout.com\/news-release\/lookout-discovers-houthi-deployed-android-surveillanceware-targeting-middle-eastern-military-forces\" rel=\"noopener\">press release<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Lookout emphasized the need for Android users to avoid apps hosted outside of Google Play, always keep their apps up to date, and be wary of excess permissions.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/houthi-aligned-apt-targets-middle-east-militaries-spyware\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A threat actor which may be aligned with Houthi rebels<\/p>\n","protected":false},"author":12,"featured_media":4391,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4390","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/houthi-aligned-apt-targets-mideast-militaries-with-guardzoo-spyware-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4390","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4390"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4390\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4391"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}